Organization boundaries
Cases, evidence, drafts, invoices, and activity records belong to one organization. Membership checks apply before workspace data is returned.
Security
Protect payment records, customer context, and team decisions with organization access controls, private evidence, human review, and a traceable case history.
Access and connected accounts
Access is checked against the organization each record belongs to.
Cases, evidence, drafts, invoices, and activity records belong to one organization. Membership checks apply before workspace data is returned.
Owners manage the workspace and billing. Analysts prepare cases. Owners and reviewers approve dispute responses.
Members use their own accounts and verify their email address before accessing organization data.
Connect Stripe through the Stripe App without sharing your Stripe password. Connected-account credentials are stored securely and available only to services that need them. Resolvely requests permissions to show cases, submit approved evidence, and confirm recovered amounts. Funds stay with your payment provider; Resolvely does not store card numbers or hold customer funds.
Evidence, review, and history
Keep the records, approval, and resulting action connected.
Files are stored privately. Authorized members receive short-lived upload and download links after access checks; there is no public file library.
An Owner or reviewer must approve every dispute response. Unsupported claims must be corrected first, and duplicate-submission safeguards protect retries.
Evidence changes, drafts, approvals, submissions, and billing events are recorded in an append-only audit log.
Drafting uses case details and supporting evidence, including text extracted from documents. Claims cite their sources, and those citations are checked before approval.
AI processing takes place in the United States through Amazon Bedrock. Resolvely and Bedrock do not use drafting content to train their models. A person reviews and approves the final wording.
Data protection
Resolvely operates across multiple AWS regions in the United States, with encryption in transit and at rest.
Case records and evidence files use AES-256 encryption. Database encryption also covers automated backups and snapshots.
HTTPS connections use TLS 1.2 or later. Secure session cookies protect sign-in, and payment-provider credentials are kept out of the browser.
Operational logs redact authorization credentials, provider signatures, and request bodies.
The privacy policy explains data use, retention, essential cookies, and the service providers involved.
Scope and disclosure
Resolvely has not completed a SOC 2 audit. Contact us for a security review. Deletion requests go to privacy@resolvely.com; a custom automated retention schedule is not currently offered.
The service is not designed for protected health information. Do not upload PHI or regulated data that requires a business associate agreement.
Report a security issue to legal@resolvely.com with the details and steps to reproduce. We acknowledge reports within 2 business days, keep you informed while we investigate, and do not pursue good-faith researchers who avoid accessing other customers' data.